Hugging Face, ClawHub Abused for Malware Distribution
Summary
Threat actors are abusing AI distribution platforms like Hugging Face and ClawHub to spread malware by uploading trojanized files (files containing hidden malicious code) that trick users into downloading them through social engineering. The attackers use indirect prompt injection (embedding hidden instructions in data that AI systems read and execute without the user knowing) to make AI agents automatically download and run malware on users' computers, with hundreds of malicious files identified across both platforms.
Classification
Affected Vendors
Related Issues
Original source: https://www.securityweek.com/hugging-face-clawhub-abused-for-malware-distribution/
First tracked: May 1, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 92%